Minnesota Confirms 30 Water Systems Hit; No US Agency Will Name Who Did It
The state activated a whole-of-government response after a coordinated attack on operational technology at community water utilities on 26–27 July. Headlines have already assigned it to Iran. Minnesota, the FBI and CISA have not.
Minnesota IT Services said on Tuesday 28 July that more than 30 community water and wastewater systems were impacted in what it called a coordinated cyberattack over the previous two nights, targeting operational technology at local utilities. “At this point, we can confirm that more than 30 water systems throughout the state were impacted,” MNIT told The Hacker News. The clearest single case is Braham, population 1,700, which posted on Monday morning that its water plant was “offline for an unknown reason” and asked residents to conserve because the tower held only a “limited quantity”; a later notice attributed the outage to “a malicious cyber-attack of computerized operating systems by unknown actors.” Plymouth and South St. Paul were among those affected, per the Star Tribune. Maple Plain declared a local state of emergency. MNIT said it knew of no requests for residents to change drinking-water use, and the Minnesota Department of Health confirmed water quality was unaffected at every impacted system. No boil-water advisories were issued.
The gap is in attribution. The Hacker News reported on 29 July that officials “have not publicly identified the attacker, affected products, exploited vulnerability, or whether data was stolen.” BleepingComputer noted the threat actor “remains unknown” while quoting agencies on the general pattern of state-sponsored pre-positioning. StateScoop called it “a cyberattack of undetermined origin.” Against that, Tech Times reported that researchers at Tenable believe the attack bears the hallmarks of CyberAv3ngers — an operation formally attributed to the IRGC — and that they suspect the use of CVE-2021-22681, an unpatchable Rockwell PLC flaw, four days after CISA updated advisory AA26-097A on roughly 22 July to widen its warning on internet-facing PLCs from Rockwell Automation, Schneider Electric, Siemens and “potentially other manufacturers.” Cybernews ran the headline “Iran hackers hit 30 Minnesota water systems.”
John Israel, MNIT’s assistant commissioner and Minnesota’s chief information security officer, framed the response rather than the culprit: “Cyberattacks against critical infrastructure require a coordinated, whole-of-government response.” The state said it worked containment, investigation, recovery and threat-intelligence sharing with CISA, the EPA, the FBI and the affected utilities. On the widened federal advisory that preceded the attacks, Joshua Corman of the Institute for Security and Technology told reporters the warning “should give everyone nightmare fuel.” The structural number sits further back: an EPA enforcement alert from March 2024 found that 70 percent of water systems inspected since 2023 were in violation of the risk-assessment and emergency-response-plan requirements of the 2018 America’s Water Infrastructure Act. The Star Tribune reports the EPA’s own view that attacks on municipal water are rising as operations grow more dependent on digital connectivity.